Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ugur Can Engin

#36045of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2008-3913
7.5
2008-05-27
Meto · Meto Forum · CVE-2008-2448
Name of the Vulnerable Software and Affected Versions: Meto Forum version 1.1 Description: The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through SQL injection vulnerabilities in various parameters, including the `id` parameter to "admin/duzenle.asp" and "admin oku.asp", the `kid` parameter to "kategori.asp" and "admin kategori.asp", and unspecified parameters to "uye.asp" and "oku.asp". Recommendations: For Meto Forum version 1.1, consider restricting access to the affected API endpoints "admin/duzenle.asp", "admin oku.asp", "kategori.asp", "admin kategori.asp", "uye.asp", and "oku.asp" until a patch is available. As a temporary workaround, avoid using the `id` and `kid` parameters in the respective affected endpoints.